Ross ROSS = Recommend OSS · open-source software intelligence for agents

cloud-gouv/securix

SécurixOS is a NixOS-based secure operating system tailored for small to medium-sized teams. It provides a minimal, hardened environment with strong isolation, reproducibility, and policy-driven configurations to ensure operational security and compliance. observed · 2026-09-03

github.com/cloud-gouv/securix · Nix observed · 2026-09-03

Health v2 · maintenance only

88/100

  • Activity 100
  • Release rhythm 100
  • Longevity 39

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 9
  • age_days: 553
  • days_rel: 2
  • days_push: 0
  • n_releases_24m: 12

Full methodology

Adoption not part of the score

1029 stars · 48 forks observed · 2026-09-03

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

SécurixOS is a NixOS-based hardened Linux distribution for secure workstations, developed by the French DINUM for sysadmin, office, and development use. It applies ANSSI hardening recommendations with TPM2, Yubikey, FIDO2 authentication, Secure Boot enrollment, and encrypted secrets management.

Use cases

  • set up a hardened secure workstation for sysadmins
  • deploy reproducible NixOS machines with ANSSI-compliant hardening
  • manage FIDO2 and Yubikey-based login and disk decryption
  • enroll Secure Boot keys centrally with TPM2 support
  • encrypt secrets with age or Vault across team machines
  • provision secure laptops for small and medium teams

When to choose

  • you need ANSSI-aligned Linux hardening out of the box
  • your team already uses NixOS and wants reproducible secure workstations
  • you rely on TPM2, Yubikey, or FIDO2 for authentication and disk encryption

When to avoid

  • you need a production-ready, supported OS today (project is alpha)
  • you do not use or want NixOS declarative configuration
  • you need Windows/macOS or non-Linux environments
  • you require a license-guaranteed distribution (no license declared yet)

Facets

application · maturity experimental

security secrets-management configuration-management security operating-systems self-hosted self-hosted nixos hardened-os anssi secure-boot tpm2 yubikey fido2 disk-encryption secure-workstation devops linux

1 source

Member repositories

RepositoryRoleHealth v2
cloud-gouv/securixmain88

For agents

markdown · JSON · MCP: product_card(name="cloud-gouv/securix")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem